389,999open jobs
10,334companies
49,652added this week
Browse all
Salary
$111k – $238k per year (Estimated)
Location
In office (Dublin)
Seniority
Architect
Employment
Full-Time
Overview
Company
Impact
Profile match
Mastercard is an American payments technology company whose origins date to 1966, when a group of banks formed the Interbank Card Association to compete with BankAmericard. Like its main rival it does not issue cards or extend credit; it operates the network that authorises, clears and settles transactions between issuing banks, acquirers and merchants in more than two hundred countries. Headquartered in Purchase, New York, the company has built a large services business alongside the core network, covering fraud and identity products through its Ethoca and RiskRecon acquisitions, open banking, consulting and loyalty programmes.

Our Purpose

Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we’re helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential.

Title and Summary

Director, Technology RiskDirector, Second Line of Defense - Technology Risk

Overview:

  • Provide independent second-line oversight, review, and validation of technology risks across markets, with a focus on Europe, ensuring alignment with IT policies, standards, controls, and regulatory expectations.
  • Support maintenance of a technology risk management framework aligned with regulatory requirements and Mastercard’s Enterprise Risk Management and Operational Risk and Control frameworks.
  • Support development of a control framework aligned with approved risk appetite, regulatory obligations, and technology risk exposure.
  • Review risk and technology-related regulatory requirements and assess the adequacy of management responses to supervisory inspections and feedback.
  • Lead the development of clear, decision-useful risk reporting for market and Group governance forums, supporting effective escalation and transparency.

Role:

Technology Risk Oversight in Market:

  • Provide independent second line oversight and constructive review of market (Europe) relevant risks and risk assessment activities focusing on Operational Resilience and Security risks, this includes risk assessments related to material product and technology changes.
  • Provide second line oversight across key control areas focusing on technology (such as change management, system availability, security, access, and data), reviewing control design, assessing operational effectiveness, and examining control testing results and assurance outcomes. Identifies, highlights and escalates material control deficiencies and remediation delays.
  • Ensure documentation and ongoing monitoring of market relevant risks focused on technology risks, controls, and issues, including security testing results, through remediation to closure in approved GRC tools.
  • Support and review security and resilience frameworks and strategies, ensuring they address threats and vulnerabilities specific to market’s specific processes, products and services.
  • Ensures technology teams develop policies and standards specific to the local market, reducing risk exposure and promoting the implementation of robust IT and security controls.
  • Oversee the development of relevant metrics focused on technology and security risk metrics, ensuring they are risk meaningful and outcomes focused, and aligned with approved risk appetite and tolerance thresholds.

Risk Management Framework:

  • Maintain and support the adoption of the Technology Risk Standard in markets and technology and contribute to the design and delivery of supporting processes and tools that meet local regulatory requirements.
  • Support the execution of the Enterprise Risk Management (ERM) and Operational Risk and Controls (ORC) Framework in market and technology groups.
  • Develop and manages local risk processes, ensuring best practices are followed and that all procedures are documented, reviewed, and refreshed regularly.
  • Support maintaining a control framework in coordination with Group First line of defense Technology and Security Risk teams.

Technology Risk Governance:

  • Act as the 2LOD Risk representative at governance forums, risk committees, and senior management discussions, providing clear, evidence-based insights to support effective decision making.
  • Review the effectiveness of risk reporting (focusing on technology risk) to management and governance committees and promotes alignment with Group standards
  • Oversee the reporting of key risk indicators to governance bodies, ensuring timely remediation actions are taken when breaches occur.

Regulatory Engagement:

  • Support regulatory examinations in Europe and across markets on matters related to risk matters and technology and security risk and controls.
  • Review and supports risk and technology related submissions to regulatory authorities.
  • Evaluates and supports the preparation of technology risk and assurance reports.

All About You:

  • Proven experience collaborating with cross functional and global teams, managing multiple stakeholders and navigating various regulatory environments.
  • Ability to manage multiple priorities, deliverables, and initiatives simultaneously in a fast paced environment.
  • Background in formal second line of defense roles, providing independent oversight rather than direct operational responsibility.
  • Proactive and curious mindset, with the ability to engage broadly across the business while maintaining focus on core responsibilities.
  • Experience advocating for policy and procedure enhancements when necessary.
  • Strong ability to identify opportunities for improvement and driving continuous enhancement.
  • Familiarity with enterprise risk and control frameworks such as ISO, NIST CSF, or other equivalent international standards.
  • Experience working with, and presenting to, senior management and governance forums.

• Excellent verbal and written communication abilities.

Corporate Security Responsibility

All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must:

  • Abide by Mastercard’s security policies and practices;

  • Ensure the confidentiality and integrity of the information being accessed;

  • Report any suspected information security violation or breach, and

  • Complete all periodic mandatory security trainings in accordance with Mastercard’s guidelines.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
389,999 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Dublin
$111k – $167k per year • Equity • Remote • Full-Time • 5+ years exp
Cybersecurity
FedRAMP
ISO 27001
NIST CSF
SOC 2
Management
ServiceNow
Apply
$77k – $101k per year • Remote • Full-Time • 2+ years exp • Bachelor's Degree
Bash
Python
DevOps
AWS
Azure
GCP
IAM
Cybersecurity
NIST CSF
Nmap
Threat Modeling
Apply
$137k – $229k per year • In office • Full-Time • 7+ years exp • Bachelor's Degree • Atlanta
Cybersecurity
ISO 27001
NIST 800-53
NIST CSF
Apply
$84k – $206k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Montreal • Pittsburgh
DevOps
IAM
Cybersecurity
ISO 27001
NIST CSF
Threat Modeling
Zero Trust
Apply
$125k – $169k per year • Equity • In office • Full-Time • 5+ years exp • Bachelor's Degree • Atlanta • Charlotte • Richmond • Raleigh
PowerShell
Python
AI/ML
AI Agents
LLM
LLM Guardrails
NIST AI RMF
DevOps
Ansible
AWS
Azure
Azure DevOps
Backstage
CI/CD
Configuration Management
GCP
Git
GitHub
GitHub Actions
GitLab
GitLab CI
Hyper-V
Jenkins
Platform Engineering
Terraform
Cybersecurity
Kyverno
NIST CSF
Cryptography
Vault
Management
ServiceNow
Apply
$79k – $155k per year (Estimated) • In office • Full-Time • Dublin
Apply
Software Engineer I 10 hours ago
$14k – $39k per year (Estimated) • In office • Full-Time • 3+ years exp • Bachelor's Degree • Pune
DevOps
Incident Management
Apply
$21k – $54k per year (Estimated) • In office • Full-Time • Pune
PowerShell
Python
Node JS
JavaScript
Node JS
Prisma
DevOps
AIOps
Amazon CloudWatch
Amazon EC2
Amazon EKS
Amazon S3
ArgoCD
AWS
AWS Lambda
Azure
Azure AKS
Azure DevOps
Bicep
Chaos Engineering
CI/CD
CloudFormation
Datadog
Docker
Dynatrace
GitHub
GitHub Actions
GitLab
GitLab CI
GitOps
Grafana
Helm
IAM
Incident Management
Istio
Jenkins
JFrog Artifactory
Kubernetes
Kustomize
Linkerd
OpenShift
Progressive Delivery
Prometheus
Rest API
Self-Healing
Service Mesh
Splunk
Terraform
Cybersecurity
Prisma Cloud
Wiz
Apply
In office • Full-Time • Dubai
Apply
$87k – $207k per year (Estimated) • In office • Full-Time • 8+ years exp • Bachelor's Degree • Singapore
C++
Java
Perl
Python
Ruby
Node JS
JavaScript
Node JS
Commander.js
DevOps
Dynatrace
Incident Management
Splunk
Apply
$102k – $234k per year (Estimated) • In office • Full-Time • 5+ years exp • Master's Degree • London • Dublin
Apply
$78k – $178k per year (Estimated) • Remote/Hybrid • Full-Time • 5+ years exp • Bachelor's Degree • Dublin
Cybersecurity
MITRE ATT&CK
Apply
$95k – $172k per year (Estimated) • In office • Full-Time • 8+ years exp • Dublin
JavaScript
Ruby
TypeScript
Ruby
Ruby on Rails
Databases
Oracle
PostgreSQL
Frontend
GraphQL
React.js
DevOps
AWS
Azure
CI/CD
Docker
GCP
gRPC
Kubernetes
Service Mesh
Cybersecurity
SOC 2
Apply
Sr. Software Engineer 7 hours ago
$87k – $188k per year (Estimated) • In office • 5+ years exp • Bachelor's Degree • Dublin
C++
Go
Java
Python
AI/ML
Flink
Spark
DevOps
CI/CD
Analytics
A/B Testing
Apply
$108k – $230k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Dublin
C#
JavaScript
SQL
Databases
Oracle
DevOps
Azure
SLI/SLO/SLA
Apply
See all jobs
This is one of many
389,999 more open roles from verified company boards, updated every day.